CVE-2021-44790

Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.


We have discovered 952,430 live websites that are affected by CVE-2021-44790.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains952,430 live websites (34% of Apache install base)
Vulnerable Versions
  • from 2.4 through 2.4.51
Vulnerable Versions Count43 versions ( 36% of all versions)


Common Weakness Enumeration

CWE-787 Out-of-bounds Write



Details

  • Published - Dec 20, 2021
  • Updated - Aug 4, 2024

Credits

  • Chamal
  • Anonymous working with Trend Micro Zero Day Initiative

Website Distribution by Country

Number of websites using CVE-2021-44790
United States289,602 websites



Germany96,611 websites
France57,706 websites
Japan42,168 websites
Russia39,465 websites
Italy34,093 websites
Netherlands33,146 websites
Singapore27,398 websites
Czech Republic26,946 websites
Canada25,640 websites

Website Distribution by TLD

Number of websites using CVE-2021-44790
.com361,095 websites
.de56,715 websites
.org43,009 websites
.net37,155 websites
.ru34,615 websites
.it30,863 websites
.nl24,330 websites
.cz22,335 websites
.pl18,745 websites
.jp18,572 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-44790

Top websites that are affected by CVE-2021-44790. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*************.***.****.****.************.net United States***
*********.net United States***
***.****.us United States*,***
***.*********.com Singapore*,***
*****.*******.com Singapore*,***
******************.com United States*,***
****.*********.net GB*,***
*******.org United States*,***
****.com United States*,***
See full domain list

FAQ

CVE-2021-44790 is Out-of-bounds Write in Apache
A total of 952,430 websites have been identified as vulnerable to CVE-2021-44790, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2021-44790 vulnerability.
Apache versions up to and including 2.4.51 are vulnerable to CVE-2021-44790.

References